Check Point has warned customers that a critical zero-day vulnerability in its Security Management and Multi-Domain Management products is being actively exploited in the wild. The flaw, tracked as CVE-2026-16232, is an authentication bypass affecting SmartConsole that lets an attacker obtain an application login token.
Once obtained, that token can be used to log in through SmartConsole with full administrator privileges, giving an attacker the ability to alter security policy and configuration across an organization’s Check Point management environment.
Check Point confirmed the vulnerability has been observed in attacks against a limited number of customers whose management environments were directly exposed to the internet without IP restrictions. The company has released patches and mitigations, published indicators of compromise, and privately notified affected customers.
CISA Adds Flaw to KEV Catalog
CISA added CVE-2026-16232 to its Known Exploited Vulnerabilities catalog, along with a Microsoft SharePoint deserialization flaw tracked as CVE-2026-50522. Under Binding Operational Directive 26-04, federal civilian agencies must remediate the Check Point vulnerability by July 25. CISA also encourages all organizations, not just federal agencies, to prioritize patching KEV-listed vulnerabilities that grant attackers total control of an asset post-exploitation.
This marks the third Check Point vulnerability added to CISA’s KEV catalog, following CVE-2026-50751 (exploited as a zero-day in May) and CVE-2024-24919, which was leveraged by threat actors in 2024.
Additional Flaws Patched
Alongside CVE-2026-16232, Check Point’s latest update addresses two related vulnerabilities discovered internally:
- CVE-2026-62144: a critical authentication bypass and privilege escalation flaw affecting Security Management and Multi-Domain Management
- CVE-2026-62145: a high-severity local privilege escalation affecting Firewall, Multi-Domain Management, and Multi-Domain Log Server products
All three vulnerabilities were found through internal analysis at Check Point, but investigation confirmed CVE-2026-16232 had already been weaponized as a zero-day before disclosure. It remains unclear who is behind the observed attacks, though the Qilin ransomware group has recently been seen targeting Check Point appliances in unrelated activity.
Organizations running Check Point Security Management or Multi-Domain Management should apply available patches immediately, restrict management interfaces from direct internet exposure, and review the published indicators of compromise for signs of prior compromise.
